An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6870 An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00046}

epss

{'score': 0.00078}


Tue, 15 Jul 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Hliu
Hliu llava
CPEs cpe:2.3:a:hliu:llava:1.2.0:*:*:*:*:*:*:*
Vendors & Products Hliu
Hliu llava

Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.
Title Open Redirect in haotian-liu/llava
Weaknesses CWE-601
References
Metrics cvssV3_0

{'score': 6.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-03-20T18:19:20.435Z

Reserved: 2024-09-27T21:28:42.062Z

Link: CVE-2024-9308

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-03-20T10:15:47.733

Modified: 2025-07-15T15:46:41.473

Link: CVE-2024-9308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.